Net-SNMP 5.0.x before 5.0.10.2, 5.2.x before 5.2.1.2, and 5.1.3, when net-snmp is using stream sockets such as TCP, allows remote attackers to cause a denial of service (daemon hang and CPU consumption) via a TCP packet of length 1, which triggers an infinite loop.
CVSS Details
- CVSS 3.1 Base Score: 7.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade net-snmp | Jul 30, 2024 | Jul 11, 2005 |
| Freebsd | — | Upgrade net-snmp | Dec 10, 2025 | Jul 5, 2005 |
| Suse | — | Upgrade net-snmp | Feb 17, 2015 | Jul 11, 2005 |
| Ubuntu | — | Upgrade snmpd | Nov 8, 2024 | Jul 11, 2005 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub